Dominik Phillips

591 posts

Dominik Phillips

Dominik Phillips

@dphillips__

Katılım Mart 2019
238 Takip Edilen126 Takipçiler
Sabitlenmiş Tweet
Dominik Phillips
Dominik Phillips@dphillips__·
Excited to be speaking at @x33fcon 2026 alongside my colleague @thefLinkk. We’ll be presenting “Fingerprinting Modern C2 Implants via Runtime Telemetry” and the tool we built as part of our research. See you there!
English
0
1
7
528
Dominik Phillips retweetledi
thefLink
thefLink@thefLinkk·
@ShitSecure The code that your 'friend' Claude provided is fundamentally flawed and also completely misimplements the concept of nested dynamic code. No need to use AI. Just read the slides.
English
2
1
1
300
Dominik Phillips retweetledi
OS Dev
OS Dev@OSdev_·
Windows kernel data structure - "_HANDLE_TABLE". Every process has one. Whenever you open a file, process, thread, token, event, or mutex, Windows creates a handle entry that maps your user-mode handle to the actual kernel object along with its access rights. This is one of the reasons security researchers spend time understanding it. Handle leaks or overly permissive handles can become powerful primitives for privilege escalation, sandbox escapes, EDR bypasses, and forensic analysis. Sometimes, you don't need to exploit memory corruption, you just need access to the right handle.
OS Dev tweet mediaOS Dev tweet media
English
2
14
112
3.8K
Dominik Phillips retweetledi
Black Hat
Black Hat@BlackHatEvents·
📢 #BHEU Call for Briefings is NOW OPEN! Got groundbreaking security research? Share your expertise with the global infosec community! 🔬 Submit your cutting-edge research 🌍 Present at Black Hat Europe 🏆 Join the world's most elite security conference Don't miss this opportunity to showcase your work on the international stage: bit.ly/4veNpve
Black Hat tweet media
English
0
3
27
5K
Dominik Phillips retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 Unauthenticated attackers are gaining SYSTEM on domain controllers with crafted packets. The vulnerability being exploited is CVE-2026-41089, a CVSS 9.8 hole in Windows Netlogon, and exploitation in the wild has been confirmed. A patch has existed since May 12. Every DC still behind is not just vulnerable, but according to the Centre for Cybersecurity Belgium are also actively being pwnd.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
16
217
1.1K
109.8K
Dominik Phillips retweetledi
Arthur "Gerhart" Khudyaev
Arthur "Gerhart" Khudyaev@gerhart_x·
Hyper-V vmms process has embedded EXDI module. It can be used for debugging guest VM attaching to it with oleaut32 bridge from custom EXDI module, even SecureBoot is enabled for guest OS. Limitations of that method are interesting still.
Arthur "Gerhart" Khudyaev tweet mediaArthur "Gerhart" Khudyaev tweet mediaArthur "Gerhart" Khudyaev tweet media
English
2
5
52
8.5K
Dominik Phillips retweetledi
OS Dev
OS Dev@OSdev_·
In windows, APCs(Asynchronous procedure calls) is a mechanism in which a function executes in the context of the specific thread. It's not an independent execution entity like a thread. void CALLBACK MyCompletionRoutine(...) { printf("Read completed!\n"); } ReadFileEx(..., MyCompletionRoutine); //Async I/O // Later SleepEx(INFINITE, TRUE); // Alertable wait Here, the completion routine runs even before SleepEx returns. Thread | |-- ReadFileEx() | |-- SleepEx(INFINITE, TRUE) | (alertable wait) | |<-- I/O completes |<-- Windows queues User APC | |-- MyCompletionRoutine() <-- APC executes | |-- SleepEx returns WAIT_IO_COMPLETION | |-- Continue execution That's how the below sequence is possible if you have proper rights to open the process handle to suspend. Btw security software can easily catch this because you're suspending a process and allocating memory etc.
OS Dev tweet media
English
2
12
76
5.9K
Dominik Phillips retweetledi
OS Dev
OS Dev@OSdev_·
This is best channel for windows Internals by @zodiacon He's one of the authors of the iconic windows Internals books. youtube.com/playlist?list=…
English
1
35
219
14.3K
Dominik Phillips retweetledi
Alan Sguigna
Alan Sguigna@AlanSguigna·
I've always been interested in Model Specific Registers (MSRs). They're rarely used by application code; they're in the domain of operating systems, hypervisors, firmware, and low-level processor features. My debugger can now selectively access these; but don't crash the system.
Alan Sguigna tweet media
English
3
6
45
5.3K
Dominik Phillips retweetledi
🅰🅳🅼
🅰🅳🅼@securityfreax·
Modern C2 implants use sleep masking & metamorphic code to stay hidden. We’re revealing how to unmask them using low-level runtime telemetry (ETW & CPU profiling) live in production including a POC with a lightweight sensor. My team will be presenting our research at x33fcon: x33fcon.com/#!s/SebastianF…
🅰🅳🅼 tweet media
English
7
64
375
28.3K
Dominik Phillips retweetledi
Aman
Aman@Amank1412·
Someone built a transparent Mario game that runs OVER IDE so can play while waiting for Copilot to write code.
English
165
583
5.8K
776.2K
Dominik Phillips retweetledi
Mandiant (part of Google Cloud)
The FLARE Learning Hub is launching with three modules: - Malware Analysis Crash Course - The Go Reverse Engineering Reference - Introduction to Time Travel Debugging (TTD) 📟 Start learning: bit.ly/41x7MXs
GIF
English
3
86
308
15.6K
Dominik Phillips retweetledi
Vaishnavi
Vaishnavi@_vmlops·
MICROSOFT BUILT A TOOL THAT CONVERTS LITERALLY ANYTHING INTO CLEAN MARKDOWN FOR YOUR LLM pdfs. word docs. excel. powerpoint. audio. youtube urls one pip install and your AI pipeline stops choking on raw files forever no custom parsers. no broken layouts. no garbled text. just clean, structured markdown your LLM can actually read github.com/microsoft/mark…
English
77
510
4.9K
802.5K